OpenClaw hardened the skill download target directory validation
Moderate severity
GitHub Reviewed
Published
Feb 18, 2026
in
openclaw/openclaw
•
Updated Feb 20, 2026
Description
Published to the GitHub Advisory Database
Feb 18, 2026
Reviewed
Feb 18, 2026
Published by the National Vulnerability Database
Feb 20, 2026
Last updated
Feb 20, 2026
Affected Packages / Versions
openclaw(npm)<= 2026.2.142026.2.15Impact
A bug in
downloadskill installation allowedtargetDirvalues from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated.In the admin-only
skills.installflow, this could write files outside the intended install sandbox.Fix Commit(s)
Acknowledgement
Thanks @Adam55A-code for reporting.
References